ASUS Live Update Client Supply-Chain Compromise: Unauthorized Modifications
CVE-2025-59374 Published on December 17, 2025

"UNSUPPORTED WHEN ASSIGNED" Certain versions of the ASUS Live Update client were distributed with unauthorized modifications introduced through a supply chain compromise. The modified builds could cause devices meeting specific targeting conditions to perform unintended actions. Only devices that met these conditions and installed the compromised versions were affected. The Live Update client has already reached End-of-Support (EOS) in October 2021, and no currently supported devices or products are affected by this issue.

Vendor Advisory NVD

Known Exploited Vulnerability

This ASUS Live Update Embedded Malicious Code Vulnerability is part of CISA's list of Known Exploited Vulnerabilities. ASUS Live Update contains an embedded malicious code vulnerability client were distributed with unauthorized modifications introduced through a supply chain compromise. The modified builds could cause devices meeting specific targeting conditions to perform unintended actions. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.

The following remediation steps are recommended / required by January 7, 2026: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weakness Type

Embedded Malicious Code

The application contains code that appears to be malicious in nature. Malicious flaws have acquired colorful names, including Trojan horse, trapdoor, timebomb, and logic-bomb. A developer might insert malicious code with the intent to subvert the security of an application or its host system at some time in the future. It generally refers to a program that performs a useful service but exploits rights of the program's user in a way the user does not intend.


Products Associated with CVE-2025-59374

Want to know whenever a new CVE is published for Asus Live Update? stack.watch will email you.

 

Affected Versions

ASUS live update Version before 3.6.6 is affected by CVE-2025-59374

Exploit Probability

EPSS
31.79%
Percentile
96.77%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.